ci: add released PR policy self-caller

Refs: PLAT-62
This commit is contained in:
Adam Moussa 2026-08-04 11:09:18 -04:00
parent 9c1ecf9428
commit bad3b46cfa
No known key found for this signature in database
5 changed files with 56 additions and 5 deletions

22
.github/workflows/policy.yaml vendored Normal file
View file

@ -0,0 +1,22 @@
name: PR Policy
on:
pull_request:
types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review]
concurrency:
group: "policy-${{ github.event.pull_request.number }}"
cancel-in-progress: true
permissions:
contents: read
issues: read
pull-requests: read
jobs:
policy:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5
secrets:
JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }}
JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }}
JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }}

View file

@ -30,6 +30,7 @@ on:
- ".github/workflows/**" - ".github/workflows/**"
- "!.github/workflows/ci.yaml" - "!.github/workflows/ci.yaml"
- "!.github/workflows/labeler.yaml" - "!.github/workflows/labeler.yaml"
- "!.github/workflows/policy.yaml"
- "!.github/workflows/release-on-merge.yaml" - "!.github/workflows/release-on-merge.yaml"
workflow_dispatch: workflow_dispatch:
inputs: inputs:

View file

@ -64,7 +64,7 @@ The supply-chain check operates in **diff mode**: for modified or renamed workfl
**`.github/workflows/release-on-merge.yaml`** — Repo automation (not callable): cuts a tag and GitHub Release for **this** repo whenever a merge to `main` changes a reusable workflow, so Dependabot has a release to advance consumer SHA pins to (see the pinning policy below). **`.github/workflows/release-on-merge.yaml`** — Repo automation (not callable): cuts a tag and GitHub Release for **this** repo whenever a merge to `main` changes a reusable workflow, so Dependabot has a release to advance consumer SHA pins to (see the pinning policy below).
**`.github/workflows/policy.yaml`** — Intentionally absent from this PR. The self-caller must pin `Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml` to a released 40-char SHA with a matching `# vX.Y.Z` comment; a mutable local `./` path reference is rejected by the supply-chain gate on modified workflow files. The follow-up PR can be opened once this PR merges and `release-on-merge.yaml` cuts the first release containing `callable-pr-policy.yaml`, then using `gh api /repos/Sea-Haven-Industries/.github/commits/vX.Y.Z --jq .sha` to obtain the pin. **`.github/workflows/policy.yaml`** — This repo's own thin caller of `callable-pr-policy.yaml`, so the PR policy gate runs on `.github`'s own PRs. Pinned to the remote SHA at v1.0.5; a local `./` path reference is rejected by the supply-chain gate. The Jira org secrets (`JIRA_CLOUD_ID`, `JIRA_SERVICE_ACCOUNT_EMAIL`, `JIRA_API_TOKEN`) must be granted to this repo before human PR checks can pass (Dependabot and supply-chain checks still run without them).
**`.github/workflows/labeler.yaml`** — This repo's own thin caller of `callable-labeler.yaml`, so the labeler runs on `.github`'s own PRs. **`.github/workflows/labeler.yaml`** — This repo's own thin caller of `callable-labeler.yaml`, so the labeler runs on `.github`'s own PRs.
@ -72,9 +72,9 @@ The supply-chain check operates in **diff mode**: for modified or renamed workfl
### Workflow templates (`workflow-templates/`) ### Workflow templates (`workflow-templates/`)
Starter workflows offered on the org's **Actions → New workflow** page: `cdk-deploy`, `ci-dotnet`, `ci-mobile-ios`, `ci-node`, `ci-python`, `ci-python-app`, `ci-static`, `ci-typescript-frontend`, `dependency-review`, `dotnet-eb-deploy`, `labeler`, `mobile-ios-deploy`, `release`, `sam-deploy`, `triage`. Each is a thin caller of the corresponding reusable workflow above (`triage` is standalone). Every template has a paired `properties.json` (name, description, icon, `filePatterns` for auto-suggestion). Replace any `REPLACE-ME` placeholders before enabling. Templates are not scanned by Dependabot, so refresh their pinned SHAs opportunistically when editing one. Starter workflows offered on the org's **Actions → New workflow** page: `cdk-deploy`, `ci-dotnet`, `ci-mobile-ios`, `ci-node`, `ci-python`, `ci-python-app`, `ci-static`, `ci-typescript-frontend`, `dependency-review`, `dotnet-eb-deploy`, `labeler`, `mobile-ios-deploy`, `pr-policy`, `release`, `sam-deploy`, `triage`. Each is a thin caller of the corresponding reusable workflow above (`triage` is standalone). Every template has a paired `properties.json` (name, description, icon, `filePatterns` for auto-suggestion). Replace any `REPLACE-ME` placeholders before enabling. Templates are not scanned by Dependabot, so refresh their pinned SHAs opportunistically when editing one.
A `pr-policy` starter template can be added to `workflow-templates/` only after the PR that introduces `callable-pr-policy.yaml` merges and `release-on-merge.yaml` cuts the first release containing it. Until then, consumer repos must add the caller workflow manually (see §3). A `pr-policy` starter template is available in `workflow-templates/`. Before the template produces passing human PR checks, the three Jira org secrets must be granted to the consumer repo (see §1).
### Ref pinning policy ### Ref pinning policy
@ -261,14 +261,14 @@ permissions:
jobs: jobs:
policy: policy:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@<full-commit-sha> # vX.Y.Z uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5
secrets: secrets:
JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }} JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }}
JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }} JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }}
JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }} JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }}
``` ```
Replace `<full-commit-sha>` with the SHA of the release that contains `callable-pr-policy.yaml`: Replace `<full-commit-sha>` with the SHA of the release that contains `callable-pr-policy.yaml`. The current pinned SHA is `9c1ecf942894b19aba5c71b85b41906c6c83b749` (v1.0.5). To resolve the SHA for a future release:
```bash ```bash
gh api /repos/Sea-Haven-Industries/.github/commits/vX.Y.Z --jq .sha gh api /repos/Sea-Haven-Industries/.github/commits/vX.Y.Z --jq .sha

View file

@ -0,0 +1,7 @@
{
"name": "Sea Haven — PR Policy",
"description": "Validates PR title convention (type/scope/Jira key), branch naming, four-section body, commit subjects, AI attribution footers, and workflow supply-chain pins via the org callable policy workflow. Requires JIRA_CLOUD_ID, JIRA_SERVICE_ACCOUNT_EMAIL, and JIRA_API_TOKEN org secrets granted to the repo.",
"iconName": "octicon-checklist",
"categories": ["Automation", "Utilities"],
"filePatterns": []
}

View file

@ -0,0 +1,21 @@
name: PR Policy
on:
pull_request:
types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review]
concurrency:
group: "policy-${{ github.event.pull_request.number }}"
cancel-in-progress: true
permissions:
contents: read
issues: read
pull-requests: read
jobs:
policy:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@9c1ecf942894b19aba5c71b85b41906c6c83b749 # v1.0.5
secrets:
JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }}
JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }}
JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }}